SC-200 Manage a security operations environment Practice Question
Your SOC team needs to ensure that all high-severity Microsoft Sentinel incidents are automatically assigned to the senior analyst on call. The team uses Microsoft Teams for communication. Which configuration should you implement?
⚠ Common exam trap
Many candidates assume a playbook alone can handle both assignment and notification, but Microsoft Sentinel automation rules are the correct mechanism for setting incident properties like owner, while playbooks are best suited for external actions like posting to Teams.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that runs when an incident is created with severity High, sets the owner to the senior analyst, and then runs a playbook to post a message to Teams.
Automation rules in Microsoft Sentinel can directly set the incident owner when an incident is created, and then trigger a playbook to post a message to Microsoft Teams. This two-step configuration ensures high-severity incidents are automatically assigned to the senior analyst on call and the SOC team is notified via Teams without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an analytics rule to set the incident owner to the senior analyst and enable Teams integration in Sentinel settings.
Why it's wrong here
Analytics rules are designed to generate alerts and incidents from log queries; they do not expose actions to set an incident's owner or configuration for Teams integration. Ownership assignment is an incident state change, which only automation rules (or manual updates) can perform. Teams integration for notifications requires a playbook/Azure Logic App, not a Sentinel setting, so this option fails to meet both requirements.
- ✗
Create a playbook that reassigns incidents and posts to Teams, and attach it to an automation rule triggered by high-severity incidents.
Why it's wrong here
A playbook, built as an Azure Logic App, can post adaptive cards to Teams and run security response actions, but it cannot directly reassign incidents because incident properties like owner are managed by the Microsoft Sentinel API and automation rules. Attaching a playbook to an automation rule is the correct pattern, but the rule itself must perform the assignment step before invoking the playbook. Therefore, this answer incorrectly relies on the playbook to handle both the assignment and the notification.
- ✗
Create a workbook that filters high-severity incidents and configure a Teams webhook in the workbook settings.
Why it's wrong here
Azure Workbook is an interactive reporting canvas that visualizes analytics data from Log Analytics workspaces, not a mechanism for incident handling or permissions to update incident ownership. Workbook settings only control parameters and visualizations; they cannot subscribe to a Teams webhook to send messages. Notification to Microsoft Teams must be accomplished through a playbook triggered by an automation rule, not by a workbook filter or workbook configuration.
- ✓
Create an automation rule that runs when an incident is created with severity High, sets the owner to the senior analyst, and then runs a playbook to post a message to Teams.
Why this is correct
An automation rule can be configured to trigger 'When incident is created' and apply a condition for Severity equals High, then perform actions such as setting the owner to the senior analyst and running a playbook. The playbook, typically an Azure Logic App with a Microsoft Teams connector, can post an adaptive card message to a Teams channel. This combined approach correctly satisfies both requirements: automated ownership assignment and proactive notification, making it the right solution.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.